Palo Alto Networks firewalls and Panorama can use external services to authenticate administrators and end users.
Enable External Authentication
Configure an external server profile. Configure a RADIUS Server Profile. Configure a TACACS+ Server Profile. Configure an LDAP Server Profile. Configure a Kerberos Server Profile.
Assign the server profile to an authentication profile. Optionally, you can assign multiple authentication profiles to an authentication sequence. Configure an Authentication Profile and Sequence. Test Authentication Server Connectivity.
Assign the authentication profile or sequence to an administrator account or to a firewall service for end users. Administrators: Configure an Administrative Account. End user services: Configure Captive Portal. Configure the GlobalProtect portal. Configure the GlobalProtect gateway.

